Disgruntled Security Researcher Just Dropped Another Windows Zero-Day, Right on Schedule
Security researcher Will Dormann confirmed the flaw works, and Microsoft says it is actively investigating a bug that could grant full system access.
- A new security vulnerability called ShieldBreak targets Windows Defender, the built-in anti-malware engine on Windows and Windows Server. If exploited, the bug allows attackers to escalate privileges from low-level user accounts to full system access.
- Security researcher Nightmare Eclipse published the proof of concept despite Microsoft's legal threats issued in May. The vulnerability reportedly builds on an earlier exploit known as RoguePlanet.
- The proof of concept is a downloadable app, meaning the exploit requires a user to manually run it. No patch currently exists to address the flaw.
- Microsoft is aware of the reported vulnerability and is actively investigating. Security researcher Will Dormann confirmed the bug works when Windows Defender is enabled.
- Users should monitor for potential security updates, as no patch exists yet to address the flaw. This underscores ongoing tensions between software developers and security researchers over zero-day disclosure practices.
16 Articles
16 Articles
Disgruntled security researcher just dropped another Windows zero-day, right on schedule
NightmareEclipse and Microsoft keep clashing over zero-day vulnerabilities in Windows. The researcher, who pledged to give Redmond security hell, is back with ShieldBreak, a new flaw in Windows Defender that can be abused to gain complete, unfettered access to a Windows device and all its data.Read Entire Article
Microsoft's nemesis returns: Nightmare Eclipse is back with a new zero day which could be bad news for Windows users
Nightmare Eclipse discloses ShieldBreak, a new Windows privilege‑escalation zero‑dayFlaw bypasses a recent patch and works on fully updated Windows 11 systemsResearcher’s ongoing exploit spree leaves multiple Windows vulnerabilities still unpatchedNightmare Eclipse has struck again! The notorious zero-day researcher with a Microsoft grudge disclosed its latest vulnerability, and just as in previous instances, they picked their timing and release…
Microsoft in race against time with scammers to fix 2 critical flaws in Windows — how to protect your PC now
Your Windows 11 PC could be at risk of malware. A new "zero-day vulnerability" known as CVE-2026-68820 has been found to be exploiting Windows PCs. Experts say this type of flaw is extra worrisome as hackers have already discovered the glitch and will be leveraging it to hack into devices worldwide.And this particular bug is in a networking component of Windows that lets attackers who have already gained basic access to your PC escalate their pr…
New Windows zero-day flaw could give hackers deep access to your PC — how to stay safe
This week two different Windows vulnerabilities were revealed that attack your PC from different angles. However, there is one unfortunate thread that connects them; both are capable of allowing a malicious actor to gain system privileges on your Windows device, and neither has been patched yet.The flaws are a zero-day vulnerability that can circumnavigate a previous RoguePlanet and a new "Plug and Pwn" attack that emulates USB devices.Read on t…
Microsoft's nemesis drops new zero-day privilege escalation vulnerability — attack grants system-level privileges, but it could already be patched
Prolific hacker and Microsoft nemesis 'Nightmare Eclipse' has just published ShieldBreak, yet another Windows zero-day vulnerability that ought to get you SYSTEM-level privileges just by running some code as a regular user. Although Eclipse has generally kept ahead of Microsoft, it seems the company may be catching up, as our own quick testing found this exploit is already detected by Defender and might even be patched as of last Tuesday.As desc…
Coverage Details
Bias Distribution
- 80% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium












